$1 QR Codes

Privacy Policy

Effective Date:
[EFFECTIVE DATE]
Last Updated:
September 23, 2026

This Privacy Policy explains how [LEGAL COMPANY NAME], which operates $1 QR Codes (internally referred to as OneDollarQR), handles information when you visit onedollarqr.com, purchase or manage a QR code, view analytics, or contact us.

1. Information we collect

Information you provide

Depending on how you use the service, you may provide an email address; a QR destination URL; a label; QR color and logo choices; an uploaded logo; reminder preferences; and purchase information such as the selected product and payment method. If you contact us, we collect your name, email address, subject, message, optional QR short code, and any files included in a support conversation.

Information created through the service

We create records needed to provide the service, including a QR short code, redirect status, creation and update times, management and analytics entitlements, aggregate scan count, payment status, secure-link records, and email delivery status.

3. Payment processing

Stripe processes payments for $1 QR Codes. Payment-card and bank-payment details are submitted to and processed by Stripe. We do not receive or store full card numbers. We keep records needed to confirm and support a purchase, which may include the purchase amount and currency, status, Stripe payment and checkout references, payment method type, card brand and last four digits, fees, refunds, and the customer email address.

4. QR destination information

We store the destination URL and the information necessary to operate each dynamic QR redirect. This may include its short code, destination URL, active status, creation time, color, logo, label, management entitlement, analytics entitlement, purchaser email, and total scan count.

5. Scan data and Detailed Analytics

Basic scan information

Every active QR maintains an aggregate total scan count. When Detailed Analytics is not active, the service records the count without creating a detailed record for each scan.

Detailed Analytics

When Detailed Analytics is active, we may also record the scan time, referring page, browser user-agent, approximate country, region and city, device type, browser, operating system, likely-bot status, and a short-lived pseudonymous visitor identifier used to estimate unique activity. Approximate location comes from network request information; we do not collect precise GPS location. A scan does not necessarily represent a unique person, and all analytics are estimates.

Raw internet protocol addresses are used transiently to process requests and produce the rotating pseudonymous identifier, but are not stored in the QR scan record.

6. Website analytics

We use Google Analytics to understand visits and interactions on the website, such as page views and product actions. Before product event details are sent, the application filters fields that could contain email addresses, destination URLs, management tokens, logo data, card data, or payment identifiers. Google may process usage, device, and network information under its own privacy terms.

7. Cookies and local storage

The website and its service providers may use cookies, local storage, and similar browser technologies for site operation, security, checkout state, authenticated staff sessions, interface preferences, and Google Analytics. The public QR purchase and management experience does not require a customer account. We do not describe or use these technologies as advertising cookies in the current service.

8. Transactional email

We use email to deliver purchase confirmations, receipts, secure QR management and code-list links, management or analytics reminders when enabled, support replies, and important service or security notices. These are transactional communications tied to the service. The current product does not use customer information for marketing email campaigns.

9. Service providers

We use service providers only where needed to operate the service, including:

  • Stripe for payment processing and payment records;
  • Lovable for hosting, managed data storage, file storage, email delivery, and service infrastructure; and
  • Google Analytics for website usage measurement.

These providers process information under their own terms and privacy commitments. We may replace or add operational providers as the service changes and will update this policy when the change is material.

10. Data retention

Minimal redirect records

The product is designed to keep a purchased QR redirect working at its last saved destination after management access ends. We may therefore retain the minimal QR record—including its short code, destination, status, and operational metadata—for an extended period while needed to provide that redirect and maintain service records.

Other records

Detailed scan records, purchase records, support messages, uploaded files, secure-link records, and email delivery records may be retained for operational, security, support, accounting, fraud-prevention, and legal purposes. Detailed Analytics data is separate from the minimal data needed to maintain the redirect. Retention periods may vary by record type and applicable obligations.

11. Your rights and requests

Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, or a portable copy of personal information. You may also ask about our handling of your information. We may need to verify your identity and authority before completing a request. Some information may need to be retained to keep a QR redirect operating, document a transaction, protect the service, or meet legal obligations. Deleting the minimal QR record will stop that QR from redirecting.

12. Security

We use reasonable technical and organizational safeguards, including access controls, restricted storage, secure-link mechanisms, and payment processing through Stripe. No internet service or storage method is completely secure, so we cannot guarantee absolute security. Customers are responsible for protecting management, code-list, receipt, and support-file links they receive.

13. Children

The service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us so we can review and address it.

14. International users

The service and its providers may process information in countries other than the one where you live. Those countries may have different data-protection laws. Where required, we rely on lawful mechanisms for international processing and transfers.

16. Changes to this policy

We may update this Privacy Policy as the service, providers, or legal obligations change. We will post the revised policy here and update the “Last Updated” date. Material changes may also be communicated through the service or by email when appropriate.

17. Contact

[LEGAL COMPANY NAME]
[MAILING ADDRESS]
[LEGAL CONTACT EMAIL]

You may also use our public contact form. Please do not send passwords, full card details, or management links in a message.